user avatar

DevSecOps Engineer

HyerTek Inc

Posted today

Job Requirements

Fort Meade, MD Columbia, MD Rockville, MD Annapolis, MD
Top Secret Polygraph not specified
Senior Level Career (10+ yrs experience)
$150,000 - $190,000

Job Description

HyerTek is a federal technology consulting firm delivering secure enterprise applications, data analytics, and modernization services to federal government agencies. HyerTek is hiring a Sr. DevSecOps Engineer to own the software supply chain and delivery pipeline behind our federal solutions — from a developer's commit through hardened container build, automated security gating, signed artifact, and accredited release into Azure Government enclaves at DoD Impact Levels 5, 6. and into sensitive compartmented environments. You will make security a property of the pipeline rather than a review at the end of it, and you will produce the continuous evidence that keeps an Authority to Operate current.

This is a hands-on, builder role. You will work embedded with a delivery team of cloud, full-stack, cybersecurity, analytics, and QA engineers rather than sitting in a separate platform organization, and you will be the single owner of the path between a merged pull request and a change running in an accredited enclave. The pipelines you build carry code into environments handling sensitive and classified data; their integrity is a security control in its own right. An invariant the customer depends on should be enforced by a failing build rather than remembered by a reviewer.

Location: This is an hybrid on-site position at Fort George G. Meade, Maryland. Candidates must be located in, or willing to relocate to, the Baltimore–Washington corridor within commuting distance of Fort Meade. Work is performed in accredited/SCIF facilities at least 2-3 days per week.

Requirements

Own CI/CD pipeline architecture across multiple repositories and release cadences in GitHub Actions and Azure DevOps, including environments that must build and deploy in disconnected and air-gapped modes.

Design and maintain hardened container builds on DoD Iron Bank base images — multi-stage builds that compile dependencies and discard the toolchain, run non-root under a hardened runtime, and survive restrictive admission policy on AKS or OpenShift.

Embed build-blocking security gates: static analysis, dynamic analysis, software composition analysis, secret scanning, container image scanning, infrastructure-as-code scanning, and license compliance — configured so a finding stops a release rather than filing a report.

Generate, attest, and retain SBOMs; implement artifact signing and provenance so that what runs in an enclave is verifiably what was built and reviewed.

Build the promotion path across environment tiers and across Impact Level boundaries, including artifact transfer into environments a pipeline cannot reach back out of.

Engineer custom policy-as-code guards that enforce system-specific invariants in CI, and keep them fast enough that developers do not route around them.

Own secrets management operations: migrate configuration to a managed vault, eliminate secrets from source control and shell history, implement per-environment separation, and build and document a rotation procedure.

Automate continuous configuration-compliance evidence — drift detection and configuration snapshots that satisfy continuous monitoring and cATO expectations rather than point-in-time scan results.
Instrument applications and pipelines for observability: structured logging with correlation IDs, health and readiness endpoints, metrics and tracing, and centralized log shipping to Azure Monitor, Log Analytics, and Microsoft Sentinel for Government with DoD-compliant audit retention.

Implement immutable, append-only audit log delivery to a write-once sink, and verify that every security-relevant event survives to it.

Own pipeline reliability as a first-class concern — a green build must mean something. Diagnose and eliminate flaky infrastructure, non-deterministic test harnesses, and resource leakage in CI.

Build and rehearse backup, restore, and disaster recovery: verified restore into an empty environment, results validated against the acceptance suites, with documented RPO and RTO.

Implement 12-factor configuration and per-environment configuration management; remove hardcoded values and environment-specific behavior from application code.

Partner with cybersecurity engineers to produce pipeline and supply-chain control evidence for RMF, SSP inputs, POA&M remediation, and ATO/cATO packages.

Support production operations: deployment, incident response hooks, root-cause analysis, and runbook authorship suitable for customer handoff.

Requirements
5+ years of hands-on DevOps/DevSecOps engineering, including ownership of production CI/CD for an accredited or otherwise regulated system.

Deep CI/CD engineering experience in GitHub Actions and/or Azure DevOps, including self-hosted runners and disconnected build patterns.

Demonstrated container hardening for DoD environments — Iron Bank or equivalent hardened base images, multi-stage builds, non-root runtime, minimal images without package managers or compilers, and image scanning to a clean result.

Production Kubernetes experience (AKS or OpenShift), including deployment manifests, liveness and readiness probes, secrets injection, and admission-policy constraints.

Proven implementation of a secure software supply chain: SBOM generation and attestation, artifact signing and provenance, dependency and secret scanning, and policy-as-code.

Strong Infrastructure as Code proficiency (Bicep/ARM or Terraform) — sufficient to build, review, and gate the environments the cloud engineering team designs.

Hands-on Azure Government delivery, including Key Vault, managed identity, Azure Policy, Azure Monitor / Log Analytics, and Microsoft Sentinel for Government.

Working knowledge of DISA STIGs, the DoD Cloud Computing SRG at IL5 and above, NIST SP 800-53, and the RMF lifecycle — enough to produce pipeline and supply-chain control evidence, not merely to consume requirements.

Secrets management at production scale: vault integration, rotation procedures, and per-environment separation with no secrets in repositories or shell history.

Strong scripting and automation in a backend language — Python, PowerShell, Node.js/JavaScript, or C#/.NET — sufficient to write custom CI guards and build tooling, not only to wire existing actions together.
Strong Linux fundamentals and command-line troubleshooting.

Practical experience instrumenting applications for observability and shipping audit logs to a SIEM with defined retention.

Backup, restore, and disaster recovery engineering, including rehearsed restores and documented RPO/RTO.

Excellent troubleshooting, documentation, and stakeholder communication skills.

Comfort working independently across multiple concurrent engagements.

DoD 8570/8140 IAT Level II baseline certification (Security+ CE minimum).

Candidates must have and maintain an active TS clearance with the Department of Defense. TS/SCI is strongly preferred; candidates holding TS must be SCI-eligible and willing to be read in.

Preferred
Prior experience achieving Iron Bank image acceptance or Platform One delivery.
Air-gapped or cross-domain delivery experience, including artifact transfer through an accredited guard.
Continuous ATO (cATO) implementation and automated control-evidence pipelines.

Kubernetes policy engines (OPA/Gatekeeper, Kyverno) and admission control.

Prior support of an RMF authorization at IL5 or above.

CISSP, CASP+, or equivalent advanced security certification.


Experience migrating an application between data tiers without regressing security invariants.


HyerTek offers a comprehensive benefits package, including:
- Medical, dental, and vision insurance
- 401(k) with employer contribution
- Paid time off (PTO) and company holidays
- Professional development and certification support
- Employee assistance program (EAP)
- Life and disability insurance

Clearance & Work Authorization
This position requires U.S. citizenship and an active TS clearance with the Department of Defense. TS/SCI is strongly preferred, and candidates holding TS must be SCI-eligible; the work is expected to require SCI access, and HyerTek will sponsor the read-in for an otherwise qualified candidate. Candidates must be authorized to work in the United States without the need for employment-based visa sponsorship now or in the future.

Salary Range
$150,000 – $190,000 annually, depending on experience and clearance status.

Equal Employment Opportunity (EEO)

HyerTek is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, age, or any other protected status.
group id: 91125207